Google’s Android Security State Libraries Enable Component-Level Security Verification

Google has unveiled its AndroidX Security State libraries, a significant advancement that allows applications to verify the security patch status at a granular level, focusing on individual components rather than relying solely on a device-wide security patch date. This innovative approach offers developers a more nuanced understanding of device security, enhancing the overall security posture of Android applications.

Centralized Security Assessment

With the launch of the AndroidX Security State and Security State Provider libraries, Google has introduced a centralized mechanism for assessing the security of Android devices. This development empowers developers to conduct more precise security verifications, providing them with the flexibility to tailor their security measures according to the specific needs of their applications.

Whether you develop security-critical, consumer-facing apps (such as banking, fintech, or healthcare) or Mobile Device Management (MDM) solutions, these libraries enable you to programmatically verify the security state of the device per component.

Traditionally, the Security Patch Level (SPL) has been a monolithic number representing the entire system software stack on an Android device. However, the new mechanism allows for component-level security verification, granting developers enhanced visibility into available remediations.

The Security State library categorizes security patch levels into three distinct types: Device SPL, Published SPL, and Available SPL. The Device SPL is directly queried from the running system without the need for network access, indicating the currently installed security patch level. The Published SPL reflects the latest patch level officially released by Google for a specific component, while the Available SPL denotes the patch level that can be downloaded and installed on the device.

By surfacing these three distinct patch levels at the component level, developers and enterprises can now understand exactly how secure a device is, identify missing patches, and take proactive remediation steps.

This granularity is particularly beneficial for banking and enterprise applications, which can leverage Device and Available SPLs to ensure a device’s security before permitting sensitive actions. Instead of merely rejecting a request, these applications can prompt users to install specific OS component updates first. Furthermore, developers can verify the patch status of specific Common Vulnerabilities and Exposures (CVEs) before allowing security-sensitive operations involving particular hardware or software components, such as NFC or Bluetooth.

The library includes functions like queryAllAvailableUpdates() and fetchAvailableSecurityPatchLevel(), which aggregate data from the current device to identify pending security updates across system components. Additionally, the areCvesPatched() function checks whether specific CVEs have been addressed on the device, while isDeviceFullyUpdated() assesses whether all available security patches have been installed. For convenience, the createVulnerabilityReportUrl() function generates standardized URLs for security bulletins and CVE details.

Complementing this, the Security State Provider library serves as a companion tool specifically designed for Original Equipment Manufacturers (OEMs). It standardizes the communication process for update clients, allowing Android apps to receive update notifications without needing to distinguish between sources such as Google Play, Google’s Over-The-Air (OTA) client, or an OEM’s proprietary update client.

For developers eager to harness real-time, component-level patch information to enhance user protection, the Understanding Device Security State guide offers comprehensive insights and instructions.

About the Author

Sergio De Simone


Show moreShow less

AppWizard
Google's Android Security State Libraries Enable Component-Level Security Verification